insecurity/threat of rpm, urpmi, apt-get installs?

From: Beowulf (beowulf_at_nowhere.net)
Date: 10/14/04


Date: Thu, 14 Oct 2004 09:59:36 -0500

Isn't it naive of us linux users to think that linux is secure when we (at
least I do) routinely install open source binary applications by means of
rpms, urpmi, apt-get? Couldn't such installs mean I am installing an
application that is the equivalent of Windows spyware, or a trojan, or
worm?

How would a linux user know they are installing apps that are not a
threat? Even compiling from souce means you are trusting the source code,
unless you are a total geek and have the hours of time to scrutinize all
the source code and locate nefarious code.

Don't get me wrong, I am a linux user, and I love linux. But the college
network administrator at my college raised this point, which seems valid.



Relevant Pages

  • Re: insecurity/threat of rpm, urpmi, apt-get installs?
    ... Couldn't such installs mean I am installing an ... > Don't get me wrong, I am a linux user, and I love linux. ... and a small portion ) scrutinize the software. ... When ) the fix is reported to the community, ...
    (comp.os.linux.security)
  • Re: [SLE] OO Installation Complete!
    ... > I followed the instructions and had a runaway script! ... confirm that the script would run, then closed the process w/o installing. ... I did note that there was a file association problem which I had ... Linux user# 313696 ...
    (SuSE)
  • Re: [opensuse] Workspaces X Wallpapers (KDE4)
    ... the mail by the guy who installed it for a new-to-linux-user. ... Nowhere in what I said about the "new" user I helped with openSUSE did ... installing to the new to Linux user is referring to a comment I made ... Linux user since he is still... ...
    (SuSE)
  • Re: [opensuse] Firefox Cant Open this Site
    ... installing when i browse this Link ... show me page as required Plugin is not installed. ... Why aren't you using Firefox 3.0.5? ... Linux User #211409 ...
    (SuSE)
  • Re: compatibility problems
    ... they'd need to provide the source code if they modified the GPLd ... Whether or not they modified the GPL code (i.e. to ... Linux User - #352034 ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)

Quantcast